GitLab released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to fix CVE-2026-90970, a critical improper neutralization vulnerability rated 9.9 on CVSS v3.1. Under certain conditions, an authenticated user with Duo Agent Platform access could submit a specially crafted flow configuration, escape the prompt template sandbox, and execute arbitrary commands on the AI Gateway. GitLab conducted targeted customer outreach before announcing the patches; the supplied notices do not report exploitation.
GitLab strongly recommends that affected Self-Hosted AI Gateway installations upgrade immediately to the applicable patched version. GitLab-hosted AI Gateways have already been patched, so GitLab.com, GitLab Dedicated, and GitLab Self-Managed customers using those hosted gateways need no action. The Canadian Centre for Cyber Security reinforced the update guidance in advisory AV26-994, identifying affected releases preceding the three fixed versions and urging administrators to review GitLab’s guidance and apply necessary updates.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
CISA added an assessment to the CVE-2026-90970 record listing exploitation as "none," rather than public proof of concept or active exploitation. GitLab's advisory did not state whether the vulnerability had been exploited.
The Canadian Centre for Cyber Security issued advisory AV26-994 concerning the GitLab AI Gateway vulnerability and linked to GitLab's critical patch release. It encouraged users and administrators to review the guidance and apply necessary updates.
GitLab released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to fix CVE-2026-90970, rated critical with a CVSS v3.1 score of 9.9, and urged affected Self-Hosted customers to upgrade immediately. Under certain conditions, an authenticated user with Duo Agent Platform access could use a crafted flow configuration to escape the prompt template sandbox and execute arbitrary commands on the gateway.
Before publishing its release announcement, GitLab conducted targeted outreach to Self-Hosted AI Gateway customers with upgrade guidance.
GitLab deployed the security fix to GitLab-hosted AI Gateways before announcing the release. GitLab.com, GitLab Dedicated, and GitLab Self-Managed customers using those hosted gateways did not need to take action.
Researcher invisiblemeerkat responsibly disclosed CVE-2026-90970, an improper neutralization vulnerability in the GitLab AI Gateway custom flow prompt template. GitLab credited the researcher in its patch announcement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcethehackernews.com
Open sourcedocs.gitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.